Code Injection Flaw in yaojingang GEOFlow's Superadmin Theme Editor
CVE-2026-82666
5.1MEDIUM
What is CVE-2026-82666?
A code injection vulnerability exists in the Superadmin Theme Editor of yaojingang GEOFlow versions up to 2.1.0. This flaw allows an attacker to manipulate the function preview of the SiteThemeEditorController.php file, leading to potential remote code execution. The exploit is already publicly available, thus emphasizing the urgency for users operating the affected version to upgrade to at least version 2.1.1, where the issue has been patched. Immediate action is recommended to mitigate risks associated with this vulnerability.
Affected Version(s)
GEOFlow 2.0
GEOFlow 2.1.0
GEOFlow 2.1.1
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
iswangxy (VulDB User)
